Safety · 4 min read ·
How to undo an AI agent’s changes safely
Snapshot before the agent starts, then undo with git restore, stash or revert. What Claude Code, Codex and Gemini CLI can rewind, and what they cannot.
What is the safest way to undo an agent’s changes?
Take a snapshot before the agent starts. A git commit or a stash is enough. Everything else in this post is a way to get back to that point.
OpenAI’s Codex CLI docs give the same advice: create Git checkpoints before and after a task so you can revert changes. Git works with every agent, sees changes made by shell commands as well as by edit tools, and does not depend on a tool’s own undo feature being switched on.
What should you do before the agent starts?
Three commands, thirty seconds.
Check that you know where you are: git status. If you have uncommitted work you want to keep, save it first. Either commit it, or run git stash push -u -m "before agent". The -u flag includes untracked files, which a plain stash leaves behind.
Move to a branch for the task: git switch -c agent/fix-login. If the result is bad, you can delete the branch and your main branch never changed.
During a long task, add checkpoints yourself. After each step that works, run git add -A && git commit -m "checkpoint: login form works". You can squash these commits before you merge.
How do you undo after the agent is done?
Start by looking: git status lists what changed, and git diff --stat shows how much. Then choose the smallest undo that fixes the problem.
One file went wrong: git restore src/auth.ts puts that file back to its last staged or committed version. git restore . does it for every tracked file under the current directory. Be careful. These commands overwrite uncommitted edits, and nothing brings them back.
You want to keep the attempt for reference: git stash push -u -m "agent attempt 1" saves your local modifications and rolls the files back to HEAD. git stash pop brings them back later.
The agent made commits: on a private branch, git reset --hard <checkpoint> moves the branch back to your checkpoint. On a branch other people use, git revert <commit> is safer, because it adds a new commit that reverses the earlier one instead of rewriting history.
You reset too far: git reflog lists where HEAD used to be. Find the commit you want and run git switch -c rescue <hash>.
The agent created files you do not want: run git clean -n first. It is a dry run that lists what would be removed. Then git clean -fd deletes them. Untracked files are not in git, so this one cannot be undone.
How do you undo one bad change and keep the rest?
Use patch mode. git restore -p walks through the changed hunks and lets you choose which ones to discard, so you can drop the one wrong edit and keep the nine good ones.
You can also work the other way around. git add -p lets you pick hunks to stage, and git’s docs describe it as a chance to review the difference before adding it. Stage what you want, commit it, and discard everything that is left with git restore .. Either way you read each hunk once, which is the review you needed to do anyway.
What do the agents’ own undo features cover?
Quick rewinds help inside a session. Know their limits.
Claude Code takes a checkpoint before each prompt. Run /rewind, or press Esc twice, and you can restore the code, the conversation or both. The checkpointing docs list what it misses. It does not track files changed by Bash commands, so an rm, mv or cp that Claude ran cannot be undone this way. Edits made by most subagents are not restored. Manual edits and changes from other sessions are normally not tracked. Anthropic’s own summary is that checkpoints are not a replacement for version control.
Gemini CLI has /rewind (also Esc twice), which can revert file changes made by its edit tools. Its docs say it does not undo manual edits or changes made through the shell. A separate checkpointing feature with /restore is off by default and has to be enabled in settings.json. See the rewind and checkpointing docs.
The pattern is the same everywhere. Built-in undo covers the tool’s own file edits. Shell commands, manual edits and anything outside the project are on you, which is why the git snapshot comes first.
What if the agent deleted something git does not track?
Then git cannot bring it back. A file that was never committed is not in the repository, and a file in .gitignore, such as a local .env or a development database, is not saved by your commits either.
Before you let an agent loose in a folder, commit new files so they are tracked, and copy anything irreplaceable, such as local data or secrets, somewhere the agent’s project folder does not reach. If something is already gone, check your editor’s local history and your system backups.
Undo that is part of the workspace
SwarmPane’s Undo for agents takes a checkpoint before every agent step that can edit your files, and rewinds that step byte for byte. A rewind refuses to overwrite edits you made since, and tells you which ones, so you do not lose your own work while undoing the agent’s.
Keep committing the work you care about. Undo is for the agent’s steps: a bad one is a one-click rewind instead of a hunt through git diff.
SwarmPane runs the agent CLIs and accounts you already have. Start with a 7-day trial for $1 and try Undo on your next risky task.